296,147
Total vulnerabilities in the database
In Apache NiFi 1.0.0 to 1.11.4, the notification service manager and various policy authorizer and user group provider objects allowed trusted administrators to inadvertently configure a potentially malicious XML file. The XML file has the ability to make external calls to services (via XXE).
Software | From | Fixed in |
---|---|---|
apache / nifi | 1.0.0 | 1.11.4.x |
![]() |
1.0.0 | 1.12.0-RC1 |